Business email compromise (BEC) operators continued to defraud organizations through social engineering-heavy email campaigns that often avoided malware and attachments, instead impersonating executives, employees, and trusted business contacts to request wire transfers, gift cards, contract payments, and invoice changes. Researchers reported that attackers abused a wide range of email infrastructure, including free and local email services, encrypted providers, self-registered look-alike domains, and compromised accounts containing stolen email threads, while also hiding malicious routing through deceptive Reply-To addresses and spoofed display names.
The activity showed increasing sophistication across industries and regions, with some campaigns using acquisition-related pretexts, telecom-themed domains, multilingual lures, and COVID-19 or tax-related narratives to pressure victims into urgent financial action. Security firms said BEC remained one of the most financially damaging cybercrime threats, particularly in the Americas and Europe, and urged organizations to combine stronger email protections with employee awareness, careful review of sender details, and out-of-band verification for payment or account-change requests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
In August 2021, the operators of the fake cryptocurrency platform added a yearly fee of 0.0005 BTC that victims had to accept after changing their password and enabling MFA. Proofpoint described this as an evolution of the scam workflow.
Trend Micro reported a consistent increase in business email compromise activity during 2021, with a sudden increase in August. The company also noted campaigns spoofing ordinary employees' display names, not just executives'.
Proofpoint observed a later version of the cryptocurrency advance-fee fraud campaign starting in July 2021. This iteration used securecoins[.]net as the landing page while preserving the same fake-account withdrawal scheme.
Proofpoint observed the first wave of an advance-fee fraud campaign in May 2021 using the landing page coins45[.]com. The phishing emails provided credentials to fake Bitcoin accounts that appeared to hold large balances.
On 2021-03-30, the U.S. Internal Revenue Service issued a security alert about an ongoing email-based IRS impersonation campaign. The activity primarily targeted educational institutions and .edu users.
Proofpoint observed a smaller campaign in March 2021 targeting financial and accounting organizations in North America with fake tax preparation requests. The emails ultimately delivered NetWire RAT through a macro-enabled downloader.
In March 2021, Proofpoint observed an IRS-themed campaign using employee retention tax credit lures tied to COVID-19 impacts on employers. It sent more than 18,000 messages to over 2,000 entities and delivered TrickBot via XLSB Excel files.
Proofpoint said TA575 began a tax-themed campaign in early March 2021 that used American Rescue Plan-themed IRS lures. The emails linked to macro-enabled Excel documents that downloaded Dridex and affected more than 1,800 organizations.
Proofpoint reported that a campaign impersonating the UK's HM Revenue and Customs began in mid-February 2021. It abused Self-Employment Income Support Scheme themes and used fake authentication pages to steal credentials.
Proofpoint observed a 500% increase in tax-themed email campaigns delivering weaponized Excel 4.0 macros in the first three months of 2021. The company assessed attackers were using the technique because modern defenses had weaker detection coverage for it.
Trend Micro launched its 'BEC Display Name Spoofing' detection for Trend Micro Cloud App Security in the first quarter of 2021. The capability was introduced to detect impersonation that abuses sender display names.
Proofpoint noted that QBot had previously been distributed through XLSB files. This was cited as prior evidence of attackers using the format to reduce detection.
Talos described a support-contract-themed business email compromise campaign first seen in mid-2020. The emails requested transfers of several thousand Euros or British pounds and often claimed a treasurer was unavailable.
Talos said attackers increasingly incorporated COVID-19 themes into business email compromise emails beginning early in 2020. These lures claimed the sender was infected or invoked pandemic-related hardship to solicit gift card purchases.
Cisco Talos reported an acquisition-themed business email compromise campaign active since late 2019. It spoofed internal senders, used reply-to domains such as trustnet-gateway[.]cc and intranetgateway[.]net, and relied on phone-based social engineering.
Trend Micro observed the Gmail account cexecutive9<BLOCKED>@gmail.com sending business email compromise messages over multiple years. The same account also drew complaints on social media from scam targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
agari.com
Open sourcetrendmicro.com
Open sourceproofpoint.com
Open sourceblog.talosintelligence.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.